Latest CVE Feed
-
7.5
HIGHCVE-2016-2086
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0729
Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) o... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2015-2774
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-2510
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8681
The ovisp driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with so... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8680
The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-8679
The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartpho... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8319
Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, a... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8318
Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, a... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8307
The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-3975
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigatio... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monito... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-3973
The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain sensitive user information by visiting webdynpro/resources/sap.com/tc~rtc~coll.appl.rtc~wd_chat/Chat#, pr... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2858
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-1714
The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bou... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-0734
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRA... Read more
Affected Products : activemq- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-8305
Huawei Sophia-L10 smartphones with software before P7-L10C900B852 allow attackers to cause a denial of service (system panic) via a crafted application with the system or camera privilege.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3948
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.... Read more
Affected Products : squid- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
8.2
HIGHCVE-2016-3947
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitiv... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1563
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025